{
  "document" : {
    "aggregate_severity" : {
      "text" : "hoch"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "Die International Components for Unicode (ICU) sind C, C++ und Java Bibliotheken zur Auswertung regulärer Ausdrücke bzw. zum Verarbeiten von Strings und Zeichen im Unicode Format.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein entfernter, anonymer Angreifer kann eine Schwachstelle in der Bibliothek ICU ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- Linux",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2024-3232 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2015/wid-sec-w-2024-3232.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2024-3232 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3232"
    }, {
      "category" : "external",
      "summary" : "Ubuntu Security Notice USN-2605-1 vom 2015-05-11",
      "url" : "http://www.ubuntu.com/usn/usn-2605-1/"
    }, {
      "category" : "external",
      "summary" : "Debian Security Advisory DSA-3187-1 vom 2015-08-02",
      "url" : "https://www.debian.org/security/2015/dsa-3323"
    }, {
      "category" : "external",
      "summary" : "Debian Security Advisory DSA-3323 vom 2015-08-03",
      "url" : "http://seclists.org/bugtraq/2015/Aug/2"
    }, {
      "category" : "external",
      "summary" : "SUSE Security Update SUSE-SU-2015:1915-1 vom 2015-11-05",
      "url" : "https://www.suse.com/support/update/announcement/2015/suse-su-20151915-1.html"
    }, {
      "category" : "external",
      "summary" : "SUSE Security Update SUSE-SU-2016:0324-1 vom 2016-02-04",
      "url" : "https://www.suse.com/support/update/announcement/2016/suse-su-20160324-1.html"
    }, {
      "category" : "external",
      "summary" : "SUSE Security Update SUSE-SU-2016:0324-1 vom 2016-02-04",
      "url" : "https://www.suse.com/support/update/announcement/2016/suse-su-20160324-1.html"
    }, {
      "category" : "external",
      "summary" : "SUSE Security Update SUSE-SU-2017:2318-1 vom 2017-09-01",
      "url" : "https://www.suse.com/support/update/announcement/2017/suse-su-20172318-1.html"
    }, {
      "category" : "external",
      "summary" : "SUSE Security Update SUSE-SU-2018:1401-1 vom 2018-05-24",
      "url" : "https://www.suse.com/support/update/announcement/2018/suse-su-20181401-1.html"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7173426 vom 2024-10-18",
      "url" : "https://www.ibm.com/support/pages/node/7173426"
    } ],
    "source_lang" : "en-US",
    "title" : "International Components for Unicode (ICU): Schwachstelle ermöglichen Ausführen von beliebigem Programmcode mit Benutzerrechten",
    "tracking" : {
      "current_release_date" : "2024-10-17T22:00:00.000+00:00",
      "generator" : {
        "date" : "2024-10-18T08:16:31.132+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.3.8"
        }
      },
      "id" : "WID-SEC-W-2024-3232",
      "initial_release_date" : "2015-05-11T22:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2015-05-11T22:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initial Release"
      }, {
        "date" : "2015-05-11T22:00:00.000+00:00",
        "number" : "2",
        "summary" : "Version nicht vorhanden"
      }, {
        "date" : "2015-05-11T22:00:00.000+00:00",
        "number" : "3",
        "summary" : "Version nicht vorhanden"
      }, {
        "date" : "2015-05-11T22:00:00.000+00:00",
        "number" : "4",
        "summary" : "Version nicht vorhanden"
      }, {
        "date" : "2015-05-11T22:00:00.000+00:00",
        "number" : "5",
        "summary" : "Version nicht vorhanden"
      }, {
        "date" : "2015-08-02T22:00:00.000+00:00",
        "number" : "6",
        "summary" : "New remediations available"
      }, {
        "date" : "2015-08-02T22:00:00.000+00:00",
        "number" : "7",
        "summary" : "Version nicht vorhanden"
      }, {
        "date" : "2015-08-03T22:00:00.000+00:00",
        "number" : "8",
        "summary" : "New remediations available"
      }, {
        "date" : "2015-11-05T23:00:00.000+00:00",
        "number" : "9",
        "summary" : "New remediations available"
      }, {
        "date" : "2015-11-05T23:00:00.000+00:00",
        "number" : "10",
        "summary" : "Version nicht vorhanden"
      }, {
        "date" : "2016-02-04T23:00:00.000+00:00",
        "number" : "11",
        "summary" : "New remediations available"
      }, {
        "date" : "2017-08-31T22:00:00.000+00:00",
        "number" : "12",
        "summary" : "New remediations available"
      }, {
        "date" : "2018-05-24T22:00:00.000+00:00",
        "number" : "13",
        "summary" : "New remediations available"
      }, {
        "date" : "2024-10-17T22:00:00.000+00:00",
        "number" : "14",
        "summary" : "Neue Updates von IBM aufgenommen"
      } ],
      "status" : "final",
      "version" : "14"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "category" : "product_name",
        "name" : "Debian Linux",
        "product" : {
          "name" : "Debian Linux",
          "product_id" : "2951",
          "product_identification_helper" : {
            "cpe" : "cpe:/o:debian:debian_linux:-"
          }
        }
      } ],
      "category" : "vendor",
      "name" : "Debian"
    }, {
      "branches" : [ {
        "category" : "product_name",
        "name" : "IBM Rational ClearQuest",
        "product" : {
          "name" : "IBM Rational ClearQuest",
          "product_id" : "5168",
          "product_identification_helper" : {
            "cpe" : "cpe:/a:ibm:rational_clearquest:-"
          }
        }
      } ],
      "category" : "vendor",
      "name" : "IBM"
    }, {
      "branches" : [ {
        "category" : "product_name",
        "name" : "Open Source International Components for Unicode (icu)",
        "product" : {
          "name" : "Open Source International Components for Unicode (icu)",
          "product_id" : "T005016",
          "product_identification_helper" : {
            "cpe" : "cpe:/a:icu_project:international_components_for_unicode:-"
          }
        }
      } ],
      "category" : "vendor",
      "name" : "Open Source"
    }, {
      "branches" : [ {
        "category" : "product_name",
        "name" : "SUSE Linux",
        "product" : {
          "name" : "SUSE Linux",
          "product_id" : "T002207",
          "product_identification_helper" : {
            "cpe" : "cpe:/o:suse:suse_linux:-"
          }
        }
      } ],
      "category" : "vendor",
      "name" : "SUSE"
    }, {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_version",
          "name" : "14.04 LTS",
          "product" : {
            "name" : "Ubuntu Linux 14.04 LTS",
            "product_id" : "T003005",
            "product_identification_helper" : {
              "cpe" : "cpe:/o:canonical:ubuntu_linux:14.04:-:lts"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "14.1",
          "product" : {
            "name" : "Ubuntu Linux 14.10",
            "product_id" : "T004096",
            "product_identification_helper" : {
              "cpe" : "cpe:/o:canonical:ubuntu_linux:14.10"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "15.04",
          "product" : {
            "name" : "Ubuntu Linux 15.04",
            "product_id" : "T004924",
            "product_identification_helper" : {
              "cpe" : "cpe:/o:canonical:ubuntu_linux:15.04"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "15.1",
          "product" : {
            "name" : "Ubuntu Linux 15.10",
            "product_id" : "T005015",
            "product_identification_helper" : {
              "cpe" : "cpe:/o:canonical:ubuntu_linux:15.10"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Linux"
      } ],
      "category" : "vendor",
      "name" : "Ubuntu"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2014-8146",
    "notes" : [ {
      "category" : "description",
      "text" : "Es existieren Pufferüberlaufschwachstellen in der ICU Bibliothek. Diese Schwachstellen werden durch Speicherverletzungen bei der Verarbeitung von speziell kodierte Daten verursacht. Ein entfernter anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebige Code mit den Rechten der Anwendung, welche die ICU Bibliothek verwendet, auszuführen oder einen Denial of Service Zustand herbeizuführen."
    } ],
    "product_status" : {
      "known_affected" : [ "T005015", "2951", "T002207", "T005016", "5168", "T003005", "T004924", "T004096" ]
    },
    "release_date" : "2015-05-11T22:00:00.000+00:00",
    "title" : "CVE-2014-8146"
  }, {
    "cve" : "CVE-2014-8147",
    "notes" : [ {
      "category" : "description",
      "text" : "Es existieren Pufferüberlaufschwachstellen in der ICU Bibliothek. Diese Schwachstellen werden durch Speicherverletzungen bei der Verarbeitung von speziell kodierte Daten verursacht. Ein entfernter anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebige Code mit den Rechten der Anwendung, welche die ICU Bibliothek verwendet, auszuführen oder einen Denial of Service Zustand herbeizuführen."
    } ],
    "product_status" : {
      "known_affected" : [ "T005015", "2951", "T002207", "T005016", "5168", "T003005", "T004924", "T004096" ]
    },
    "release_date" : "2015-05-11T22:00:00.000+00:00",
    "title" : "CVE-2014-8147"
  } ]
}